peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

615 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-44077 KEV Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentica… Patch first 9.8 critical 93.3% 2021-11-29
CVE-2020-2551 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected… Patch first 9.8 critical 93.2% 2020-01-15
CVE-2021-40870 KEV An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows… Patch first 9.8 critical 93% 2021-09-13
CVE-2024-6670 KEV In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted pa… Patch first 9.8 critical 93% 2024-08-29
CVE-2016-3427 KEV Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confid… Patch first 9.8 critical 92.3% 2016-04-21
CVE-2022-26258 KEV D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. Patch first 9.8 critical 92% 2022-03-28
CVE-2020-10148 KEV The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability coul… Patch first 9.8 critical 92% 2020-12-29
CVE-2022-37042 KEV Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing auth… Patch first 9.8 critical 91.9% 2022-08-12
CVE-2024-11680 KEV ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… Patch first 9.8 critical 91.7% 2024-11-26
CVE-2022-26352 KEV An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose file… Patch first 9.8 critical 91.6% 2022-07-17
CVE-2026-20182 KEV May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed i… Patch first 10.0 critical 91.5% 2026-05-14
CVE-2026-85706 KEV GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 1… Patch first 10.0 critical 91.4% 2026-09-12
CVE-2025-9242 KEV An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… Patch first 9.8 critical 91.3% 2025-09-17
CVE-2024-13160 KEV Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… Patch first 9.8 critical 91.2% 2025-01-14
CVE-2021-35211 KEV Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If e… Patch first 9.0 critical 91.2% 2021-07-14
CVE-2026-1731 KEV BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code executi… Patch first 9.8 critical 91% 2026-02-06
CVE-2017-12149 KEV In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFi… Patch first 9.8 critical 90.7% 2017-10-04
CVE-2024-40711 KEV A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). Patch first 9.8 critical 90.4% 2024-09-07
CVE-2016-8735 KEV Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12… Patch first 9.8 critical 90.3% 2017-04-06
CVE-2025-37164 KEV A remote code execution issue exists in HPE OneView. Patch first 10.0 critical 90.2% 2025-12-16
CVE-2020-29583 KEV Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can b… Patch first 9.8 critical 90.2% 2020-12-22
CVE-2023-40044 KEV In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tra… Patch first 10.0 critical 90.2% 2023-09-27
CVE-2024-13161 KEV Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… Patch first 9.8 critical 90.1% 2025-01-14
CVE-2020-17463 KEV FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. Patch first 9.8 critical 89.7% 2020-08-13
CVE-2019-7195 KEV This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… Patch first 9.8 critical 89.7% 2019-12-05
CVE-2019-17621 KEV The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system… Patch first 9.8 critical 89.6% 2019-12-30
CVE-2025-26399 KEV SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if expl… Patch first 9.8 critical 89.5% 2025-09-23
CVE-2018-14839 KEV LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with pa… Patch first 9.8 critical 89.4% 2019-05-14
CVE-2021-20021 KEV A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP requ… Patch first 9.8 critical 88.7% 2021-04-09
CVE-2025-61757 KEV Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.… Patch first 9.8 critical 88.6% 2025-10-21
← previous page 12 of 21 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt